{"id":"CVE-2026-95208","title":"An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via providing crafted Certificate Authority certificates, leading to valid certifica…","summary":"An issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via providing crafted Certificate Authority certificates, leading to valid certifica…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-295"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:34:48.800","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-95208","references":[{"url":"http://wolfssl.com","label":"cve@mitre.org"},{"url":"https://gist.github.com/lkloliver/14edf8bbfbf5769949b85c7f5cc2eba2","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-08T16:52:14.773Z","slug":"CVE-2026-95208","body":"## Overview\n\nAn issue in the ConfirmNameConstraints() function (wolfcrypt/src/asn.c) of wolfSSL v5.9.1 and v5.9.2 allows attackers to cause a Denial of Service (DoS) via providing crafted Certificate Authority certificates, leading to valid certificates without SAN to be incorrectly rejected by wolfSSL-based TLS clients.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":218302,"id":"CVE-2026-95208","ts":1791497737174,"field":"cvss","old":null,"new":"7.5"},{"seq":218301,"id":"CVE-2026-95208","ts":1791497737174,"field":"severity","old":"none","new":"high"}]}